MEDIUM
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack
Published May 19, 2014
6.8
MEDIUMCVSS 2.0
EPSS 1.27%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.